ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1134.002
Create Process with Token
MalwareAria-body

Aria-body has the ability to execute a process using runas.

T1134.002
Create Process with Token
MalwareWhisperGate

The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`.

T1134.002
Create Process with Token
MalwarePipeMon

PipeMon can attempt to gain administrative privileges using token impersonation.

T1134.002
Create Process with Token
MalwareKONNI

KONNI has duplicated the token of a high integrity process to spawn an instance of cmd.exe under an impersonated user.

T1134.002
Create Process with Token
MalwareREvil

REvil can launch an instance of itself with administrative rights using runas.

T1134.002
Create Process with Token
MalwareZxShell

ZxShell has a command called RunAs, which creates a new process as another user or process context.

T1134.002
Create Process with Token
MalwareAzorult

Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges.

T1134.002
Create Process with Token
ToolEmpire

Empire can use Invoke-RunAs to make tokens.

T1134.002
Create Process with Token
ToolPoshC2

PoshC2 can use Invoke-RunAs to make tokens.

T1134.003
Make and Impersonate Token
MalwareMafalda

Mafalda can create a token for a different user.

T1134.003
Make and Impersonate Token
MalwareCobalt Strike

Cobalt Strike can make tokens from known credentials.

T1134.003
Make and Impersonate Token
ToolSILENTTRINITY

SILENTTRINITY can make tokens from known credentials.

T1134.004
Parent PID Spoofing
MalwareDarkGate

DarkGate relies on parent PID spoofing as part of its "rootkit-like" functionality to evade detection via Task Manager or Process Explorer.

T1134.004
Parent PID Spoofing
MalwarePipeMon

PipeMon can use parent PID spoofing to elevate privileges.

T1134.004
Parent PID Spoofing
MalwareKONNI

KONNI has used parent PID spoofing to spawn a new `cmd` process using `CreateProcessW` and a handle to `Taskmgr.exe`.

T1134.004
Parent PID Spoofing
MalwareCobalt Strike

Cobalt Strike can spawn processes with alternate PPIDs.

T1134.005
SID-History Injection
ToolEmpire

Empire can add a SID-History to a user if on a domain controller.

T1134.005
SID-History Injection
ToolMimikatz

Mimikatz's MISC::AddSid module can append any SID or user/group account to a user's SID-History. Mimikatz also utilizes SID-History Injection to expand the scope of other components such as generated Kerberos Golden Tickets and DCSync beyond a single domain.

T1135
Network Share Discovery
MalwareTrickBot

TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API.

T1135
Network Share Discovery
MalwareQuietSieve

QuietSieve can identify and search networked drives for specific file name extensions.

T1135
Network Share Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about shares on remote hosts.

T1135
Network Share Discovery
MalwareStuxnet

Stuxnet enumerates the directories of a network resource.

T1135
Network Share Discovery
MalwareAvosLocker

AvosLocker has enumerated shared drives on a compromised network.

T1135
Network Share Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat and Net to discover network shares.

T1135
Network Share Discovery
MalwareSardonic

Sardonic has the ability to execute the `net view` command.

T1135
Network Share Discovery
MalwareRansomHub

RansomHub has the ability to target specific network shares for encryption.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1135
Network Share Discovery
MalwareBad Rabbit

Bad Rabbit enumerates open SMB shares on internal victim networks.

T1135
Network Share Discovery
MalwareEmotet

Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`.

T1135
Network Share Discovery
MalwareOlympic Destroyer

Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares.

T1135
Network Share Discovery
MalwareDUSTTRAP

DUSTTRAP can identify and enumerate victim system network shares.

T1135
Network Share Discovery
MalwareBADHATCH

BADHATCH can check a user's access to the C$ share on a compromised machine.

T1135
Network Share Discovery
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can identify network shares connected to the victim machine.

T1135
Network Share Discovery
MalwareWastedLocker

WastedLocker can identify network adjacent and accessible drives.

T1135
Network Share Discovery
MalwareInvisiMole

InvisiMole can gather network share information.

T1135
Network Share Discovery
MalwareWhisperGate

WhisperGate can enumerate connected remote logical drives.

T1135
Network Share Discovery
MalwareConti

Conti can enumerate remote open SMB network shares using NetShareEnum().

T1135
Network Share Discovery
MalwareDiavol

Diavol has a `ENMDSKS` command to enumerates available network shares.

T1135
Network Share Discovery
MalwareBlackCat

BlackCat has the ability to discover network shares on compromised networks.

T1135
Network Share Discovery
MalwareIcedID

IcedID has used the `net view /all` command to show available shares.

T1135
Network Share Discovery
MalwareShimRat

ShimRat can enumerate connected drives for infected host machines.

T1135
Network Share Discovery
MalwareAvaddon

Avaddon has enumerated shared folders and mapped volumes.

T1135
Network Share Discovery
MalwareFlagpro

Flagpro has been used to execute `net view` to discover mapped network shares.

T1135
Network Share Discovery
MalwareHELLOKITTY

HELLOKITTY has the ability to enumerate network resources.

T1135
Network Share Discovery
MalwareBabuk

Babuk has the ability to enumerate network shares.

T1135
Network Share Discovery
MalwarePlugX

PlugX has a module to enumerate network shares.

T1135
Network Share Discovery
MalwareCuba

Cuba can discover shared resources using the NetShareEnum API call.

T1135
Network Share Discovery
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use loop operations to enumerate network resources.

T1135
Network Share Discovery
MalwareClambling

Clambling has the ability to enumerate network shares.

T1135
Network Share Discovery
MalwareAkira

Akira can identify remote file shares for encryption.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.